There are couple of alternatives you have in lieu of client to steer Linux and other servers or even guest wifi traffic.
Eproxy over Internet. All SWG customers tenants come provisioned with an eproxy domain on port 8081 (Settings > Explicit Proxy)
IPSEC or GRE Tunnels to Netskope DC of your choice (with active standby failover to a backup DC)
Explicit Proxy over IPSEC / GRE what Netskope calls it as EPoT (Explicit Proxy over Tunnel). There is universal IP address that Netskope provides with this option over port 8080.
Note that I wouldn't mix Guest wifi and Server traffic together on same Tunnel if you have a flat non-segmented server network. i.e you want Decrypt Server traffic but not the guest wifi. Corresponding SSL Do Not Decrypt policy can then be created by source subnet.